Synced 12 Sept 2026 01:32 UTC Account
← All products

CVE-2018-19943

HIGH severity · CVSS 8 · Cross-site scripting (XSS) · actively exploited (CISA KEV)
8CVSS HIGH exploited ransomware
Actively exploited in the wild (CISA Known Exploited Vulnerabilities). Known use in ransomware campaigns. Added to KEV 2022-05-24. US federal agencies must patch by 2022-06-14.

Summary

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges requiredLow
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)18%

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products we track (1)

QTS

Recommendation

This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.